Changelog for
libsss_sudo-2.2.3-13.fc31.x86_64.rpm :
* Wed Feb 26 2020 Michal Židek
- 2.2.3-13- Resolves: upstream#4159 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly
* Wed Feb 26 2020 Michal Židek - 2.2.3-12- Resolves: upstream#4135 - util/sss_ptr_hash.c: potential double free in `sss_ptr_hash_delete_cb()`
* Wed Feb 26 2020 Michal Židek - 2.2.3-11- Resolves: upstream#4118 - sssd requires timed sudoers ldap entries to be specified up to the seconds
* Wed Feb 26 2020 Michal Židek - 2.2.3-11- Add sssd-dbus package as a dependency of sssd-tools
* Wed Feb 26 2020 Michal Židek - 2.2.3-10- Resolves: upstream#4142 - sssd_be frequent crash
* Wed Feb 26 2020 Michal Židek - 2.2.3-9- Resolves: upstream#4131 Force LDAPS over 636 with AD Provider
* Wed Feb 26 2020 Michal Židek - 2.2.3-8- Resolves: upstream#3630 - Randomize ldap_connection_expire_timeout either by default or w/ a configure option
* Wed Feb 26 2020 Michal Židek - 2.2.3-7- Resolves: upstream#4135 - util/sss_ptr_hash.c: potential double free in `sss_ptr_hash_delete_cb()`
* Wed Feb 26 2020 Michal Židek - 2.2.3-6- Resolves: upstream#4088 - server/be: SIGTERM handling is incorrect
* Wed Feb 26 2020 Michal Židek - 2.2.3-5- Resolves: upstream##4089 Watchdog implementation or usage is incorrect
* Wed Feb 26 2020 Michal Židek - 2.2.3-4- Resolves: upstream#4126 pcscd rejecting sssd ldap_child as unauthorized
* Wed Feb 26 2020 Michal Židek - 2.2.3-3- Resolves: upstream#4127 - [Doc]Provide explanation on escape character for match rules sss-certmap
* Wed Feb 26 2020 Michal Židek - 2.2.3-2- Resolves: upstream#4129 - sssctl config-check command does not give proper error messages with line numbers
* Wed Feb 26 2020 Michal Židek - 2.2.3-1- Update to latest released upstream version- https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_2_2_3.htm
* Tue Oct 22 2019 Adam Williamson - 2.2.2-3- Resolves: rhbz#1755643 - Upgrade to sssd 2.2.2-1.fc30 breaks setting up FreeIPA replica in containers
* Tue Oct 22 2019 Adam Williamson - 2.2.2-2- Resolves: rhbz#1757224 - Tickets act like they\'re expiring prematurely when using KCM cache
* Wed Sep 11 2019 Michal Židek - 2.2.2-1- Update to latest released upstream version- https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_2_2_2.html- https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_2_2_1.html
* Tue Aug 27 2019 Mohan Boddu - 2.2.0-5- Rebuilding for libldb 2.0.5
* Sat Jul 27 2019 Fedora Release Engineering - 2.2.0-4- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Fri Jul 05 2019 Jakub Hrozek - 2.2.0-3- Resolves: rhbz#1721636 - sssd-kcm calls sssd-genconf which triggers nscd warning
* Fri Jul 05 2019 Jakub Hrozek - 2.2.0-2- Resolves: rhbz#1724717 - sssd-proxy crashes resolving groups with no members
* Mon Jun 17 2019 Michal Židek - 2.2.0-1- Update to latest released upstream version- https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_2_2_0.html
* Wed Mar 27 2019 Michal Židek - 2.1.0-2- Resolves: upstream#3867 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers unreadable by SSSD.- CVE-2018-16838
* Wed Mar 27 2019 Michal Židek - 2.1.0-1- Update to latest released upstream version- https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_2_1_0.html
* Wed Feb 13 2019 Sinny Kumari - 2.0.0-9- Resolves: rhbz#1667444 - sssd: make python3-sssdconfig as suggest
* Wed Feb 13 2019 Adam Williamson - 2.0.0-8- Resolves: rhbz#1676946 - startup fail with status NOTIMPLEMENTED
* Sun Feb 03 2019 Fedora Release Engineering - 2.0.0-7- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Wed Dec 12 2018 Adam Williamson - 2.0.0-6- Resolves: rhbz#1654537 - sbus: use 120 second default timeout- Backport two other patches from master to fix build with recent krb5
* Wed Nov 07 2018 Michal Židek - 2.0.0-5- Resolves: rhbz#1629737 - sssd: Remove python2 (sub)packages from Fedora 30+
* Wed Aug 29 2018 Michal Židek - 2.0.0-4- Resolves: upstream#3821 - crash related to sbus_router_destructor()- Resolves: upstream#3810 - sbus2: fix memory leak in sbus_message_bound_ref- Resolves: upstream#3819 - sssd only sets the SELinux login context if it differs from the default- Resolves: upstream#3807 - The sbus codegen script relies on \"python\" which might not be available on all distributions- Resolves: upstream#3820 - sudo: search with lower cased name for case insensitive domains- Resolves: upstream#3701 - [RFE] Allow changing default behavior of SSSD from an allow-any default to a deny-any default when it can\'t find any GPOs to apply to a user login.- Resolves: upstream#3828 - Invalid domain provider causes SSSD to abort startup- Resolves: upstream#3500 - Make sure sssd is a replacement for pam_pkcs11 also for local account authentication- Resolves: upstream#3812 - sssd 2.0.0 segfaults on startup- Resolves: upstream#3826 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: upstream#3827 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: upstream#3830 - Printing incorrect information about domain with sssctl utility- Resolves: upstream#3489 - p11_child should work wit openssl1.0+- Resolves: upstream#3750 - [RFE] man 5 sssd-files should mention necessary changes in nsswitch.conf- Resovles: upstream#3650 - RFE: Require smartcard authentication- Resolves: upstream#3334 - sssctl config-check does not check any special characters in domain name of domain section- Resolves: upstream#3849 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: upstream#3855 - session not recording for local user when groups defined- Resolves: upstream#3802 - Reuse sysdb_error_to_errno() outside sysdb- Related: upstream#3493 - Remove the pysss.local interface
* Wed Aug 29 2018 Michal Židek - 2.0.0-3- Resolves: rhbz#1622760 - Console login as FreeIPA domain user fails in current Fedora Rawhide / 29
* Wed Aug 29 2018 Michal Židek - 2.0.0-2- Fix linking issues
* Tue Aug 14 2018 Michal Židek - 2.0.0-1- New upstream release 2.0.0
* Sat Jul 14 2018 Fedora Release Engineering - 1.16.2-6- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Mon Jul 02 2018 Miro Hrončok - 1.16.2-5- Rebuilt for Python 3.7
* Mon Jun 25 2018 Fabiano Fidêncio - 1.16.2-4- Related: upstream#941 - return multiple server addresses to the Kerberos locator plugin- Related: upstream#3652 - kdcinfo doesn\'t get populated for other domains- Resolves: upstream#3747 - sss_ssh_authorizedkeys exits abruptly if SSHD closes its end of the pipe before reading all the SSH keys- Resolves: upstream#3607 - Handle conflicting e-mail addresses more gracefully- Resolves: upstream#3754 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries- Related: upstream#3219 - [RFE] Regular expression used in sssd.conf not being able to consume an AATT-sign in the user/group name.- Resolves: upstream#3766 - CVE-2018-10852: information leak from the sssd-sudo responder
* Thu Jun 21 2018 Fabiano Fidêncio - 1.16.2-3- Resolves: rhbz#1591804 - something keeps /lib/libnss_systemd.so.2 open on minimal appliance image, breaking composes
* Tue Jun 19 2018 Miro Hrončok - 1.16.2-2- Rebuilt for Python 3.7
* Mon Jun 11 2018 Fabiano Fidêncio - 1.16.2-1- New upstream release 1.16.2- https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_2.html
* Thu May 24 2018 Fabiano Fidêncio - 1.16.1-9- Related: upstream#3742 - Change of: User may not run sudo --> a password is required
* Thu May 17 2018 Fabiano Fidêncio - 1.16.1-8- Revert 589d1a48 as the builders are back to f27
* Wed May 16 2018 Fabiano Fidêncio - 1.16.1-7- Related: upstream#3436 - Certificates used in unit tests have limited lifetime- Add: \"ExcludeArch: armv7hl\"
* Mon May 14 2018 Fabiano Fidêncio - 1.16.1-6- Related: upstream#3436 - Add openssl, openssh and nss-tools as BuildRequires
* Mon May 14 2018 Fabiano Fidêncio - 1.16.1-5- Related: upstream#3436 - Certificates used in unit tests have limited lifetime- Resolves: upstream#3725 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal- Resolves: upstream#3726 - SSSD with ID provider \'ad\' should give a warning in case the ldap schema is manually changed to something different than \'ad\'.- Related: upstream#2653 - Group renaming issue when \"id_provider = ldap\" is set.- Resolves: upstream#3719 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Resolves: upstream#3728 - Request by ID outside the min_id/max_id limit of a first domain does not reach the second domain- Resolves: upstream#3731 - nss_clear_netgroup_hash_table(): only remove entries from the hash table, do not free them- Resolves: upstream#3595 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set
* Sat May 05 2018 Fabiano Fidêncio - 1.16.1-4- Resolves: rhbz#1574778 - sssd fails to download known_hosts from freeipa
* Fri Apr 27 2018 Fabiano Fidêncio - 1.16.1-3- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change- Resolves: upstream#3558 - sudo: report error when two rules share cn- Tone down shutdown messages for socket activated responders- IPA: Qualify the externalUser sudo attribute- Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15- Resolves: upstream#3402 - Support alternative sources for the files provider- Resolves: upstream#3646 - SSSD\'s GPO code ignores ad_site option- Resolves: upstream#3679 - Make nss netgroup requests more robust- Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured- Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing- Improve docs/debug message about GC detection- Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound?- Resolves: upstream#2653 - Group renaming issue when \"id_provider = ldap\" is set.- Document which principal does the AD provider use- Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs- Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM- Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Add gcc to build dependencies
* Fri Mar 30 2018 Fabiano Fidêncio - 1.16.1-2- Resolves: upstream#3573 - sssd won\'t show netgroups with blank domain- Resolves: upstream#3660 - confdb_expand_app_domains() always fails- Resolves: upstream#3658 - Application domain is not interpreted correctly- Resolves: upstream#3687 - KCM: Don\'t pass a non null terminated string to json_loads()- Resolves: upstream#3386 - KCM: Payload buffer is too small- Resolves: upstream#3666 - Fix usage of str.decode() in our tests- A few KCM misc fixes
* Fri Mar 09 2018 Fabiano Fidêncio - 1.16.1-1- New upstream release 1.16.1- https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html